CVE-2026-67822
Tenda W6-S 1.
criticalEPSS 0.5%
Description
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
Metrics
Show all metrics
Severity
critical
87.11
no public PoC known
9.8
Published
2026-07-31 17:16 UTC
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-07-31 17:16 UTC· cve@mitre.org
- Affected: n/a
- Description: Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
- Reference: https://github.com/Tristerjh/Tenda/blob/main/Tenda_W6-S_GO_overflow.md